Privacy Policy
Last updated July 21, 2026
Overview
This Policy explains how Doorpost handles personal information. We act as a service provider (processor) for the property and tenant data our customers put into the Service, and as the controller for the account and usage data we collect directly.
Information we collect
Account information: your name, email, company name, and password (stored hashed by our authentication provider).
Customer Data you enter: property, unit, lease, tenant, applicant, vendor, and financial records. You control what you put in and are responsible for having the right to provide it.
Financial connectivity: if you link a bank or card, a third-party provider (e.g., Plaid) supplies transaction data; we store access tokens securely server-side and never expose them to the browser.
Payment information: handled by our payment processor (e.g., Stripe). We don't store full card numbers. When tenants pay rent online, their bank or card details go directly to Stripe; we receive only payment confirmations.
Signature records: when a document is e-signed, we record the typed name, the document, and the time of signing as part of the lease record.
Usage data: basic logs, device/browser information, and error diagnostics (what went wrong and the browser it happened in), used to operate, debug, and secure the Service.
How we use information
To provide, maintain, secure, and improve the Service; to process payments; to communicate with you about your account; and to comply with legal obligations. We do not sell personal information.
Sharing & subprocessors
We share information with vendors that help us run the Service, under contracts that limit their use of it — for example: cloud database/hosting, application hosting, bank connectivity, payments, and transactional email providers. We may disclose information if required by law or to protect rights and safety.
Who can access your data
Your account is isolated. Row-level security walls each account's data off from every other customer — no other Doorpost customer can see your properties, tenants, documents, or finances. A tenant using the resident portal can see only their own lease, balance, payment history, and documents.
Uploaded files stay private. The documents you upload — leases, receipts, notices, signed PDFs — are held in private storage and are served only to you (or to the specific tenant a document belongs to) through short-lived, expiring links. They are never made public, never indexed by search engines, and never shared with other customers.
Our access is limited and purpose-bound. Like any hosted software, Doorpost's team holds administrative access to the infrastructure that stores your data, which is necessary to run, secure, back up, and support the Service. We do not access, read, or review the documents and content you upload in the ordinary course of business. We access customer content only when it is necessary to provide support you have requested, investigate a security incident or abuse, keep the Service operating, or comply with a valid legal obligation.
We never sell your data, never share it for advertising, and never use the documents or content you upload to train AI models. Any in-product suggestions (such as categorizing your bank transactions) are computed only from your own account's history to help you — never pooled with, or used to profile, other customers.
Tenant & applicant data
Where our customers (landlords/managers) enter their tenants' or applicants' information, that customer is the controller of that data and is responsible for providing any required notices and obtaining any required consents. We process it only to provide the Service to that customer.
If you're a tenant using the portal: we process your information on your landlord's behalf to run it — your contact details, lease and payment history, maintenance requests, and lease signatures. When you pay rent online, your bank or card details go directly to Stripe, our payment processor; we receive confirmation of the payment (amount, date, and payment method type), never your full card or account number. Your landlord controls this data: to correct or delete your information, contact your landlord, and we'll help them carry it out. You can also write to hello@getdoorpost.com and we'll route your request.
Data retention
We keep information for as long as your account is active or as needed to provide the Service, then delete or de-identify it within a reasonable period, unless a longer period is required by law.
Security
We use technical and organizational measures to protect information, including row-level data isolation between accounts, encryption in transit, and access controls. No system is perfectly secure, but we work to protect your data and to notify you of incidents where required.
Your choices & rights
You can access and update your account information in the app and can request export or deletion of your data. Depending on where you live, you may have additional rights over your personal information; contact us to exercise them.
We send occasional setup and product emails to customers — every one has an unsubscribe link, and opting out never affects essential account emails like receipts, billing notices, and password resets.
Children
The Service isn't directed to children and isn't intended for anyone under 18.
Changes
We may update this Policy; material changes will be posted here with a new date.
Contact
Privacy questions: hello@getdoorpost.com.